Question on permission/flag: QUERY_ALL_PACKAGES, usesCleartextTraffic
My scanner just got a few new checks, which were now triggered by your app with today's update:
```
! repo/dev.zwander.mastodonredirect_34.apk declares flags: usesCleartextTraffic
! repo/dev.zwander.mastodonredirect_34.apk declares risky permissions: android.permission.QUERY_ALL_PACKAGES
```
I have an idea about that permission (but please tell me nevertheless), but do you really need `usesCleartextTraffic` here? Are there any Mastodon servers **not** secured via https? If there are good reasons, both things can be added to the allow-list for your app. But if not, they'd better be fixed on your end :wink: Thanks!
关闭于 2024-01-18 8 条评论